Cybersecurity for businesses

Contact

New Hospital of Toledo: a cybersecurity department without building one

Outsourced cybersecurity departmentContinuous CIS Controls v8 assessmentsENS + GDPR compliance

The challenge

Healthcare is one of the world's most critical sectors: highly sensitive patient data and uninterrupted 24/7 operations where any disruption has direct consequences for patient care. The IT services provider supporting the New Hospital of Toledo — one of Spain's largest hospitals — needed to reach the highest levels of cybersecurity and meet stringent regulatory requirements. Building and maintaining an in-house team with that expertise represented a significant investment in both time and resources.

The solution

We became the organisation's outsourced cybersecurity department, providing CISO as a Service and a dedicated Security Team as a Service, taking full responsibility for its internal cybersecurity programme:

  • Audits and security frameworks — regular assessments based on the CIS Critical Security Controls (v8).
  • Active defence — comprehensive system and server hardening to minimise the attack surface.
  • Governance and compliance — ongoing assurance of healthcare cybersecurity and data protection obligations, including the Spanish National Security Framework (ENS) and GDPR.

The results

  • Maximum healthcare resilience — systematic hardening and CIS Controls implementation significantly strengthened hospital systems against threats such as ransomware, supporting uninterrupted care.
  • Confidence in compliance — regulatory requirements and audits met with dedicated specialists managing an increasingly complex landscape.
  • Greater efficiency and focus — the IT provider optimised costs and freed its internal teams to deliver high-quality technology services to the hospital.